MEDIUM

CVE-2026-4526

Silabs Emberznet 2026-06-25 CVSS v3.1
CVSS
6.5

Description

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

Summary dbcve.org

In EmberZNet v9.0.2 and earlier, malformed global ZCL (Zigbee Cluster Library) messages from an authenticated device (one already joined the network) trigger out-of-bounds reads in the framework's ZCL parsing logic, causing the process to terminate.

Mitigation

Update to EmberZNet v9.0.3 or later once available; restrict network join permissions and monitor for anomalous ZCL message patterns from joined devices.

Weakness (CWE)

CWE-125 Out-of-bounds Read

EPSS Score

0.44%
Probability of exploitation in next 30 days
37.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE